Skip to content

fix(seismic): certbot no longer gates consensus, renewal survives reboot - #80

Merged
samlaf merged 1 commit into
seismicfrom
sl/sei-820-fix-certbot-gates-consensus-and-certificate-renewal-is-lost
Oct 8, 2026
Merged

samlaf merged 1 commit into
seismicfrom
sl/sei-820-fix-certbot-gates-consensus-and-certificate-renewal-is-lost

Conversation

@samlaf

@samlaf samlaf commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

reth and summit had After=/Requires=nginx-ssl-setup.service, so a failed Let's Encrypt issuance kept the execution and consensus clients down, although neither needs public HTTPS. Drop that edge; tdx-init ordering is still carried by persistent-luks-setup.

certbot-renew.timer was enabled at runtime by nginx-ssl-setup, which the tmpfs rootfs forgets on reboot, and its WantedBy=timers.target is masked by the debloat script. Enable it at build time into minimal.target.wants instead, and gate certbot-renew.service on /persistent/nginx/.certbot-done so it is skipped on nodes that never obtained a certificate.

nginx-ssl-setup.service said WantedBy=multi-user.target and reached minimal.target only through the ln -sf in mkosi.postinst's enable loop. With it on minimal.target, every unit in the loop is, so systemctl enable creates each link and the ln -sf goes.

The CI image-contents check now expects certbot-renew and nginx-ssl-setup, with the minimal.target.wants links of the two enabled units. Update the module readme to match.

Fixes SEI-820

reth and summit had After=/Requires=nginx-ssl-setup.service, so a failed
Let's Encrypt issuance kept the execution and consensus clients down,
although neither needs public HTTPS. Drop that edge; tdx-init ordering is
still carried by persistent-luks-setup.

certbot-renew.timer was enabled at runtime by nginx-ssl-setup, which the
tmpfs rootfs forgets on reboot, and its WantedBy=timers.target is masked
by the debloat script. Enable it at build time into minimal.target.wants
instead, and gate certbot-renew.service on /persistent/nginx/.certbot-done
so it is skipped on nodes that never obtained a certificate.

nginx-ssl-setup.service said WantedBy=multi-user.target and reached
minimal.target only through the ln -sf in mkosi.postinst's enable loop.
With it on minimal.target, every unit in the loop is, so systemctl enable
creates each link and the ln -sf goes.

The CI image-contents check now expects certbot-renew and nginx-ssl-setup,
with the minimal.target.wants links of the two enabled units. Update the
module readme to match.

Refs: SEI-820
@samlaf
samlaf requested a review from a team as a code owner October 8, 2026 15:30
@linear-code

linear-code Bot commented Oct 8, 2026

Copy link
Copy Markdown

SEI-820

@samlaf
samlaf merged commit dbab6a5 into seismic Oct 8, 2026
5 checks passed
@samlaf
samlaf deleted the sl/sei-820-fix-certbot-gates-consensus-and-certificate-renewal-is-lost branch October 8, 2026 15:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant